Configuring Local Authentication
119
n
ov
do
cx (e
n)
16
Ap
ril 20
10
3.2.1 Creating Basic or Form-Based Authentication Classes
1
In the Administration Console, click
Devices > Identity Server > Edit > Local > Classes
.
2
Click
New
to launch the
Create Authentication Class Wizard
.
3
Specify a display name, then select a class from the
Java class
drop-down menu.
The following classes are recommended only for testing purposes:
BasicClass:
Uses basic HTTP authentication.
PasswordClass:
Passes the user name and password over HTTP in readable text, and uses
a form-based login to collect the name and password.
RadiusClass:
RADIUS enables communication between remote access servers and a
central server. For a production environment, use ProtectedRadiusClass.
For a production environment, select one of the following protected classes:
X509Class:
Certificate-based authentication. See
Section 4.2, “Configuring Mutual SSL
(X.509) Authentication,” on page 140
.
ProtectedBasicClass:
The BasicClass, protected by HTTPS.
ProtectedPasswordClass:
The PasswordClass, protected by HTTPS (form-based).
ProtectedRadiusClass:
The RadiusClass, protected by HTTPS. See
Section 4.1,
“Configuring for RADIUS Authentication,” on page 139
for configuration steps.
KerberosClass:
The authentication class used for using Kerberos for Active Directory
and Identity Server authentication. See
Section 5, “Configuring for Kerberos
Authentication,” on page 159
for configuration steps.
NMASAuthClass:
The authentication class used for Novell Modular Authentication
Services (NMAS), which uses fingerprint and other technology as a means to authenticate
a user. For instructions on using the NMAS NESCM method, see
Section 4.6,
“Configuring Access Manager for NESCM,” on page 149
.
NPOrRadiusOrX509Class:
The authentication class that allows the creation of a
contract from which the user can select an authentication method: name/password,
RADIUS, or X.509. For configuration information, see
Section 4.3, “Creating an ORed
Credential Class,” on page 145
.
PasswordFetchClass:
The authentication class that allows the Identity Server to retrieve
the user’s password when the user has used a non-password class for authentication. For
configuration information, see
Section 4.5, “Configuring Password Retrieval,” on
page 148
.
OpenIDClass:
The authentication class that allows you to configure the Identity Server to
trust the provider or providers of OpenIDs. For configuration information, see
Section 4.4,
“Configuring for OpenID Authentication,” on page 147
.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...